Risk and compliance

3-D Secure 2 without the friction: authenticate only when it counts

Strong authentication stops fraud, but every extra step costs sales. How HansaPay decides when to challenge a payment and when to let it through.

Sofia LindqvistHead of Risk and Compliance2 min read

Every payments team faces the same trade-off. Ask customers to authenticate every payment, and you stop more fraud but lose good sales at checkout. Ask them never, and conversion looks great until the chargebacks arrive.

3-D Secure 2 was designed to break that trade-off. Here is how we use it.

A quick refresher

3-D Secure is the protocol behind "verify it's you" prompts from a customer's bank. The first version was clunky: redirects, passwords, and pop-ups that looked like phishing. Conversion suffered.

Version 2 is different. It shares far more data with the issuer, including device details and transaction history, so the issuer can approve most payments without asking the customer to do anything. That's called a frictionless flow. Only payments that look risky get a challenge, usually a quick confirmation in the banking app.

payments pass frictionlessly
Most
typical challenge in a banking app
1 tap
shift to the issuer when authenticated
Liability

When authentication is required

In the European Economic Area and the UK, strong customer authentication is required by regulation for most online card payments. There are exemptions, including:

  • Low-value payments, below a set threshold.
  • Low-risk transactions, when the acquirer's fraud rate is below regulatory limits.
  • Merchant-initiated transactions, such as subscription renewals after the first authenticated payment.

Outside those regions, authentication is optional. It can still be worth using for higher-risk payments, because an authenticated payment generally shifts fraud liability from you to the issuer.

How HansaPay decides

Every payment passes through our risk engine before we decide whether to request authentication. The engine considers:

  1. The regulatory requirement for the card and region.
  2. The available exemptions, applied automatically where they're allowed.
  3. The risk score of the payment, based on device, behaviour and network-wide signals.
  4. Your preferences, such as always authenticating above a certain amount.

Measuring the result

The goal isn't the lowest possible challenge rate or the lowest possible fraud rate. It's the most good revenue. We track three numbers together, and so should you:

  • Authorisation rate, the share of attempted payments that are approved.
  • Challenge rate, the share of payments where the customer had to authenticate.
  • Fraud rate, measured by chargebacks as a share of volume.

All three are reported in your dashboard, per country and per payment method, so you can see exactly what authentication is costing and saving you.

All articles

Go live by this time tomorrow.

Open an account, share your first payment link, and start taking payments from customers anywhere.

  • Approved in about 24 hours
  • Test mode from day one
  • No long-term contract
  • Settle in 135+ currencies or USDT